fedomex[.]com
fedomex.com 网络钓鱼与安全检查
“Fedomex: Elon Musk’s Official Crypto Casino Powered by Blockchain”
fedomex.com — 内容不可用 (HTTP 502). 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of fedomex.com, observed as offline as of July 23 2026, shows a recent infrastructure supporting a brand‑impersonation campaign targeting x.com. The domain was registered on 21 February 2026 and immediately resolved to the IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The TLS certificate presented is identified as WE1, indicating a valid‑looking HTTPS endpoint. The page title returned from the site, “Fedomex: Elon Musk’s Official Crypto Casino Powered by Blockchain”, aligns with the declared scam type of a crypto‑related fraud.
The campaign uses the publicly known “Gambler Scam” phishing kit, a template frequently employed to lure victims into cryptocurrency investment schemes. VirusTotal scans have recorded 13 detections out of 93 security vendors, confirming that multiple anti‑malware engines flag the domain as malicious. The domain is listed on at least one security blocklist and has been actively blocked by the PhishDestroy service. The site impersonates x.com, suggesting that any communications referencing the brand may be spoofed to drive users toward the fraudulent casino offering.
While the offline status indicates the current hosting has been taken down, the rapid creation date and the use of a reputable CDN point to a short‑lived, opportunistic operation. Defenders should continue to monitor the IP address 188.114.97.3 for re‑use, enforce brand‑monitoring rules for x.com, and ensure that URL filtering solutions include fedomex.com in their deny lists. Additional investigation of the WE1 certificate may reveal whether it was issued to a legitimate entity or forged for this campaign. Organizations should also advise users to treat any unsolicited messages promising crypto casino rewards as malicious and to report such URLs to their incident response teams.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。